Repository navigation
Releases: MrOz59/Hermes
Release list
Hermes nightly (v0.6.0+d0f18d7)
Rolling nightly build of Hermes from the main branch.
- Version:
v0.6.0+d0f18d7 - Commit: d0f18d7
- Built: 2026-10-06T13:19:07+11:00
These artifacts are automatically rebuilt on every push to
mainand may be unstable. For tagged releases see the
non-prerelease entries.
v0.6.0
Hermes 0.6.0
Hermes 0.6.0 is the companion release for Hermes-KMS 0.4.0. It brings HDR10
streaming from Hermes-KMS virtual displays on KDE, a much faster capture path
on NVIDIA, virtual displays on Hyprland, exclusive and mirrored layouts on
GNOME, and packages that install on current Ubuntu and Fedora again.
Highlights
- HDR10 from Hermes-KMS virtual displays. On KDE, with Hermes-KMS 0.4.0
loaded withhdr_enable=1 color_depth=10, a client that asks for HDR gets a
10-bit HEVC Main10 or AV1 stream tagged with the PQ/BT.2020 colour and
mastering metadata the driver reports for each frame. Hermes matches the
virtual output's HDR setting to each client on launch and resume, so an SDR
phone after an HDR TV still gets SDR. A client that asks for HDR where the
output or driver cannot provide it gets SDR, with a warning in the log.
Contributed by @UsmanTariq2 (#45). - Much faster NVIDIA capture. NVIDIA sessions on a Hermes-KMS display copy
each frame through the CPU, and that copy used to cost more than it should.
It now takes 1.5 ms per 1440p frame instead of 6.5 ms, and 3 ms at 4K instead
of 21.5 ms, which is too slow for 60 fps. Frames are uploaded by DMA from
page-locked memory, and 10-bit frames are converted to P010 in CUDA. HDR
testing on a GTX 1060 confirmed that the periodic lag seen before is gone. - NVENC on GTX 10-series and older cards again. Every package builds with
CUDA 12.9, the last toolkit that still generates code for Maxwell, Pascal and
Volta (#43). - Virtual displays on Hyprland, through Hyprland's own headless outputs
instead of a virtual DRM device, which Hyprland cannot drive. - GNOME: exclusive and mirrored layouts now work. Touch, pen and absolute
pointer input land on the streamed display, and a desktop layout that GNOME
rewrites during a session (a monitor plugged in, the Displays panel opened)
is followed instead of leaving input offsets wrong. ext-image-copy-capture, the protocol that replaced wlr-screencopy, gives
Hermes a capture path on compositors that never implemented wlr-screencopy.- Game Mode.
hermes-gamemodeis added to Steam as a non-Steam shortcut,
for entering a pairing PIN or restarting Hermes without leaving Game Mode.
Hermes also starts in SteamOS/CachyOS Game Mode now, where it used to stay
inactive. - Virtual display cards on demand. With
hermes-kms-card-brokerinstalled,
an exhausted Hermes-KMS session pool is answered with a new card instead of a
refusal. - Clearer diagnostics. At startup Hermes reports what the running session
supports, feature by feature, with the fix for anything missing. During a
stream, the log now says when the client stops sending anything, and when a
key-frame request follows such a gap. That is what a client whose Wi-Fi drops
out looks like from the host.
Packaging
- The
.debis built for each supported Ubuntu LTS (24.04 and 26.04) and the
.rpmfor each supported Fedora (43 and 44), so each links against libraries
its release actually ships. The Fedora package installs on a current Fedora
again. - The container image no longer needs
SYS_ADMINto stream the desktop. - Nightly builds carry the commit they were built from in their version.
Security
- The Game Mode console's bearer token is rejected for WAN peers, even when Web
UI logins are allowed from the WAN. - Installing Hermes no longer breaks polkit for everyone on the host. The
isolated-session rule took its arguments in the wrong order and failed every
authorization check on the machine.
Notable fixes
- A host with no routable IPv6 address can stream again.
- Wayland capture on a machine with two GPUs allocates its buffers on the
compositor's GPU instead of streaming black
(#37). - Absolute input on wlroots compositors is mapped in the compositor's logical
space (#38). - The Hestia capabilities document advertises only virtual display backends
that can be selected (#39). capture=kwinwith Hermes-KMS is treated as KMS instead of disabling every
capture source (#47).- Hermes explains when a per-app Mirror or Extend layout overrides the global
exclusive-display setting (#48). - Reconfiguring the build no longer risks deleting the source shaders
(#49).
Notice
Independent client sessions (hermes_kms_isolated_sessions) are being
re-evaluated and are not recommended. The prototype will change in ways that
are not backwards compatible; see the changelog for what is known to be broken.
Compatibility
- Hermes-KMS UAPI 11 remains the minimum. UAPI 13 adds session binding
revocation and diagnostics. HDR needs UAPI 14, which is Hermes-KMS 0.4.0. - HDR on NVIDIA needs an encoder with HEVC Main10 or AV1 10-bit support. Check
with the running encoder probe rather than by GPU generation.
Thanks
@UsmanTariq2 for HDR10 capture and three fixes (#45, #47, #48, #49), and for
testing the NVIDIA path on a Pascal card. @danielbaldwin47 for the Wayland
capture, input and Hestia fixes (#37, #38, #39). @RZhyvitskyi for the Hyprland
headless backend (#32).
The full list of changes is in the
changelog.
v0.5.1
Hermes 0.5.1
Hermes 0.5.1 is the stable companion release for Hermes-KMS 0.3.2. It focuses
on compositor integration and fixes the GNOME/Mutter and KDE/KWin paths without
bringing in the newer cursor/UAPI v11 work reserved for Hermes 0.6.0 and
Hermes-KMS 0.4.x.
Highlights
- GNOME/Mutter virtual-display reliability. Hermes now waits for Mutter to
adopt a newly connected Hermes-KMS output, applies the client-requested mode
through a verified temporaryApplyMonitorsConfigtransaction, and confirms
that Mutter kept the requested layout. This fixes black or mismatched streams
caused by capturing one geometry while Mutter rendered another
(#22). - Safe cleanup of phantom GNOME outputs. A stale boot-time
initial_enabled=1output is removed from Mutter's active layout without
rewriting the user's savedmonitors.xmland without leaving the desktop
with no physical monitor. - Correct KDE/KWin modes. KScreen is explicitly given the resolution and
refresh requested by the client, the result is read back and verified, and
mid-session mode changes use the same compositor-aware path. - Compositor-aware behavior and diagnostics. KWin, Mutter and Hyprland are
classified separately from the generic wlroots control path, with clearer
explanations when a compositor cannot provide a requested virtual-display
feature. - Input and backend fixes. Absolute pointer coordinates include the virtual
display's desktop offset, EVDI device-creation failures are detected
correctly, and fallback to a physical display now explains why no virtual
display was requested. - Reproducible Linux packages. The release restores the FFmpeg/build-deps
snapshot compatible with the Ubuntu package builder, avoiding the
vaMapBuffer2link failure from the intervening snapshot.
Compatibility
- Hermes version: 0.5.1
- Recommended driver: Hermes-KMS 0.3.2
- Supported Hermes-KMS interfaces in this line: UAPI 7, 8 and 9
- AMD RDNA3 verification: video was confirmed on an RX 7800 XT (Navi 32).
The black-stream report in #22
was a generic Hermes-KMS imported-scanout re-export bug fixed in 0.3.2, not a
GPU-generation limitation.
Cursor-plane capture and Hermes-KMS UAPI v11 are intentionally not part of
this release. They remain on the development branch for Hermes 0.6.0 with
Hermes-KMS 0.4.x.
Known limitations
- GNOME exclusive-display mode remains unsupported.
- Hyprland virtual displays remain a diagnosed but unsupported path.
Full changelog: v0.5.0...v0.5.1
v0.5.0
Hermes 0.5.0
Hermes 0.5.0 is a substantial Linux and Hermes-KMS release. It expands virtual-display support from a single basic session into experimental multi-client and isolated-session architectures, adds NVIDIA NVENC capture, introduces a runtime container for image-based distributions, separates Hermes configuration from Sunshine/Apollo, and fixes a broad set of capture, packaging, Web UI, authentication, and shutdown issues.
Highlights
- NVIDIA NVENC for Hermes-KMS virtual displays. NVIDIA sessions now capture the driver's system-memory DMA-BUF through a validated CPU copy and feed the normal RAM-to-CUDA upload path. AMD and Intel continue using the existing VAAPI zero-copy import path. The copy waits on exported write fences, uses
DMA_BUF_IOCTL_SYNC, and validates framebuffer layout against the real DMA-BUF size before mapping (#19). - Experimental shared-desktop multi-output. With
hermes_kms_multi_output, one Hermes server can assign simultaneous Moonlight clients separate Hermes-KMS outputs, capture pipelines, modes, and absolute-input geometry in the host compositor session. This requires Hermes-KMS UAPI 8 or newer and enough outputs configured withoutputs=N(#10). - Prototype independent client sessions. With
hermes_kms_isolated_sessions, each client can receive its own Hermes-KMS DRM card, runtime directory, compositor, application process tree, capture pipeline, and tagged virtual input devices. Gamescope application sessions and Weston desktop sessions are supported. This requires Hermes-KMS UAPI 9 and remains disabled by default while audio and real concurrent-client behavior are validated (#10). - Runtime container image.
packaging/containerprovides a headless Sway environment with audio, XWayland, and optional Steam Big Picture support. It is intended for image-based systems such as Bazzite, Fedora Silverblue, and SteamOS, where only the Hermes-KMS kernel module must live on the host. Adapted from SOVLOOKUP/hermes-sunshine and the work offered in #6. - Hermes now owns its configuration directory. Linux and macOS installations use
~/.config/hermes(or$XDG_CONFIG_HOME/hermes) withhermes.confandhermes_state.json, rather than sharing Sunshine's directory. Existing Sunshine data is copied and renamed on first start, while the original remains available to Sunshine and Apollo (#14). - Nightly update channel. The Web UI updater can opt into the rolling
nightlyprerelease withnotify_pre_releases. Nightly checks compare both the semantic version and exact build commit, and stable/nightly update checks now point toMrOz59/Hermes.
Virtual display and capture fixes
- Unprivileged Hermes-KMS hosts no longer fail virtual-display startup with a 503. Hermes preserves the display's own name, accepts a present KMS driver without requiring
CAP_SYS_ADMIN, lists active Hermes-KMS displays during lookup, and loads EGL lazily so bootstrap cannot call through an uninitialized glad pointer (#17). - NVIDIA desktop OpenGL can now import foreign system-memory DMA-BUFs through
glEGLImageTargetTexStorageEXTwhen the GLES-style OES bind fails. Every capture path validates the bind instead of continuing with a broken texture (#20). - Distro-packaged CUDA toolkits build correctly again:
/usr/includeis treated as implicit so nvcc does not break GCC'sinclude_nextchain (#17). - The virtual-display watchdog is joined during shutdown, and teardown is idempotent, preventing aborts from a joinable thread and double-closing DRM file descriptors (#17).
- EVDI displays now use the requested refresh rate instead of silently describing every tabulated resolution as 60 Hz. Pixel clocks are derived from the request, and values too large for the EDID field are clamped and logged.
- KDE exclusive mode now disables every physical monitor, not only the primary one, and restores each output with its previous priority when the session ends (#12).
- Virtual-output activation now retries while a compositor has not published its first complete output layout, fixing startup races in headless and newly started container sessions (#6).
- Hermes-KMS diagnostics now report UAPI compatibility, device/output counts, multi-output and multi-device capabilities, selected output numbers, private seat-broker readiness, and the client assigned to each active virtual display.
- A disposable VM test verifies that two isolated sessions receive distinct real uinput devices and udev/libseat assignments.
Web UI, TLS, and recovery
- Chromium-based browsers can log in again. Hermes now configures the TLS session ID context required when the same listener supports client-certificate authentication and session resumption. This fixes
ERR_SSL_PROTOCOL_ERROR/Failed to fetchfailures that appeared after the first successful page request (#14). - The config UI no longer triggers a browser client-certificate selection prompt. Hermes advertises its own certificate as the acceptable CA, while paired Hestia clients continue presenting their certificate normally (#14).
- Login, create-password, and change-password pages now provide browser-console diagnostics for unreachable hosts, certificate failures, connection resets/refusals, dismissed certificate prompts, extensions, HTTP status, response body, resolved URL, timing, origin, protocol, and browser.
- Create-password and change-password no longer freeze after a failed request, and non-200 responses report their actual status instead of always claiming an internal server error (#14).
- Missing Web UI assets now produce an explicit startup diagnostic and HTTP 500 with the missing path instead of a silent blank 200 response.
hermes --credscan recover from an unreadable state file. The old file is moved to<state file>.unreadablebefore fresh credentials are written, preserving paired-client data for recovery (#14).- Port-bind failures now explain that another host may already be using the port and report the correct HTTP/HTTPS port pair.
Packaging and distribution
- Debian and RPM packages now compile the correct
/usr/share/hermesasset path, fixing Web UI pages that previously resolved under/usr/assets(#15). - Debian and RPM packages include the complete shader tree with symlinks dereferenced, so Linux capture no longer installs dangling or missing shader assets.
- Package dependencies now cover the libraries Hermes actually links against, including GLVND/OpenGL, ICE, SM, Xext, Wayland cursor/EGL/server libraries,
libva-x11on Debian, andopuson RPM. The incorrect RPMlibopusencdependency was removed. - The Arch/CachyOS package is now named
hermes-streamingto avoid colliding with the unrelatedhermesPAM package in the AUR. Executable, service, assets, and user configuration paths are unchanged. - Release artifacts are available as Debian, Fedora/RPM, and Arch packages below.
Session behavior and safety
- Cancelling an isolated launch now interrupts in-progress preparation and compositor waits, including the handoff into the active-runtime registry, so a late runtime cannot appear after
/cancelreturns. - Cancelling between HTTP launch and the RTSP handshake invalidates the pending launch. Per-client termination also stops only that client's active stream.
- Remote Input is rejected while independent sessions are enabled, avoiding accidental fallback to shared host input devices with no unambiguous target.
- Exclusive virtual-display mode is intentionally ignored while shared-desktop multi-output is enabled so physical monitors and other clients' outputs remain active.
Upgrade notes
- Existing Sunshine configuration is migrated by copying it into Hermes' new configuration directory; the Sunshine copy is retained. Hermes, Sunshine, and Apollo still use the same default ports, so only one can run at a time.
hermes_kms_multi_outputandhermes_kms_isolated_sessionsare experimental and disabled by default.- The runtime container currently serves one session and is not intended to be combined with multi-output or isolated-session mode.
- The Windows build is not part of the current release pipeline; the published artifacts target Linux.
Contributors
Special thanks to @teodorgross for the unprivileged Hermes-KMS bootstrap fixes, NVIDIA EGL/CUDA groundwork, and NVENC capture implementation in #17, #20, and #19, and to @SOVLOOKUP for the runtime-container work and compositor startup-race report.
Full changelog: v0.4.1...v0.5.0
v0.4.0
Changes since v0.3.0.
All three packages (Arch, Debian/Ubuntu, Fedora) now ship with NVIDIA NVENC hardware encoding.
Added
- Appliance-mode groundwork (dormant). A new
appliance_modeconfig flag (off by default) and a read-onlyplatf::appliance_readiness()that reports whether the host could boot straight into a headless/Gamescope streaming session — Gamescope availability, virtual-display availability, autologin detection, and the session environment. Surfaced underappliancein the diagnostics runtime view. No boot/login orchestration exists yet and enabling the flag has no runtime effect; this only paves the way for a future activation path.
Changed
-
Package and install paths rebranded
apollo→hermesfor side-by-side installs. Packagehermes, binary/usr/bin/hermes, assets/usr/share/hermes, systemd unithermes.service, and thehermes-monitor-recoveryhelper (state dir moved to~/.local/state/hermes). Noprovides/conflictsare declared, so Hermes can be installed alongside theapollo(AUR) andsunshinepackages — nothing collides. Artemis protocol extensions and the internal Windows service name are unchanged, so client compatibility is preserved.Upgrade note: the systemd unit is now
hermes.service(notsunshine.service). After upgrading, enable it once:systemctl --user enable --now hermes. -
NVENC parity across all packages. The Debian/Ubuntu (
.deb) and Fedora (.rpm) packages are now built with the CUDA toolkit, matching the Arch package, so NVIDIA users get hardware encoding on every distribution. (Fedora builds with the gcc13 compat toolchain, required by nvcc 12.6.) -
CI gates every build on the test suite. The
build-*jobs nowneeds: [test], so nothing is compiled, released, or published as nightly unless the tests pass first. Pushing avX.Y.Ztag re-runs test → build → release to promote a nightly into a stable, freshly built release. -
Unified Arch packaging on
makepkg. CI builds the Arch package straight from thePKGBUILD, so CI and a localmakepkg -siproduce the identicalhermes-*.pkg.tar.zst. Removed the orphanbuild-pkg.sh(stale, hardcoded to 0.1.0 and the old evdi dependency).
Full changelog: v0.3.0...v0.4.0
v0.3.0
Added
- Hermes-KMS driver diagnostics symmetric with EVDI: a
HERMES_KMS_DIAGNOSTICprobe distinguishes module-not-loaded, module-not-installed, DKMS build failure, UAPI-too-old, missing-capabilities, and device-node-missing, exposed via a newGET /api/hermes-kms/statusendpoint and thehermesKmsInfoblock in/api/config. - Manual install/repair tutorial for the Hermes-KMS backend in the Audio/Video tab, with per-diagnostic steps and the exact DKMS commands.
- Home page now surfaces driver-not-ready warnings for the selected virtual-display backend (EVDI or Hermes-KMS) and points to the Audio/Video install guide.
Changed
scripts/bump-version.shnow also updates the PKGBUILDpkgver(and resetspkgrelto 1), keeping the version shown in the WebUI/logs in lockstep with theVERSIONfile.
Fixed
makepkg -sino longer aborts on a fresh clone:evdimoved from a hard dependency to an optional one (it is AUR-only and needed only at runtime for virtual displays).- Desktop entry: corrected the icon reference (
apollo, notapollo.svg) and the launch command (systemctl start --user, previously the broken--u). - Application description now mentions the Hestia and Artemis clients instead of only Artemis.
v0.2.0
Hermes v0.2.0 — the first real release
This is Hermes' first proper, non-prerelease build. Until now everything came
out as rolling nightlies; v0.2.0 is the point where the basic roadmap is in
place and the host is stable enough to hand to someone who isn't us.
Where we started (0.1.0)
The 0.1.0 baseline already had the thing that makes Hermes Hermes: the
Hermes-KMS zero-copy capture path (DRM/KMS, frames handed off as DMA-BUFs
instead of copied through RAM), with EVDI still supported as a fallback, and
full Hestia / Moonlight / Artemis protocol compatibility. What it didn't have
was much of a way to see what the host was actually doing, or to behave well
across the messier parts of a real Linux desktop. That's what this release is
about.
What's new in 0.2.0
You can finally see what the host is doing. The diagnostics endpoint went
from "is the clipboard up?" to a real runtime view:
- The real encoder in use — codec, hardware vs. software, and why it
chose that. If a hardware encoder failed probing and we fell back to software,
that's now an honest field, not a buried log line. - Live pipeline metrics straight from the encode loop: FPS, bitrate,
encode time, capture-to-encode latency, encoded/dropped frame counts, and the
active stream resolution. - Hermes-KMS device counters read directly from the driver's
GET_METRICS
ioctl — frame updates, frame acquires, DMA-BUF exports, frame waits, hotplugs,
output enable/disable counts. This is the zero-copy path reporting on itself,
which only Hermes can do because it owns the capture pipeline. - A streaming-readiness preflight that rolls these signals into a single
"is the host ready to stream, and if not, what's wrong" check.
Sessions are more honest and observable. The host now records why a
session ended and distinguishes a client that dropped (network loss / crash)
from one that quit cleanly, and surfaces reconnection state in diagnostics:
whether an app is parked waiting for a reconnect, how long since the last
session ended, and how often clients have been dropping.
It plays nicer with real desktops.
- Gamescope: detects whether it's running in a desktop session or a
standalone Gamescope session, can route capture directly into Gamescope, and
exposes a configurable backend with a Hermes-branded launcher andHERMES_*
environment. - GNOME / Mutter: virtual-display support (verify-only on Mutter, since it
won't let us configure the output), with diagnostics that say so plainly
instead of pretending it worked. - systemd: the user service now waits for the graphical session and imports
its environment (DISPLAY/WAYLAND_DISPLAY/XDG_RUNTIME_DIR, audio socket,
session bus), so capture and launched apps (Steam/Lutris) get what they need
instead of silently failing when started at login.
Foundations. A single-source version scheme (the VERSION file drives
everything), a one-step release script, rolling nightly prereleases, a
GoogleTest suite running in CI under xvfb, and a couple of host-crashing bugs
caught by that suite and fixed.
Compatibility
Unchanged: the nvhttp / RTSP / control path that Moonlight and
ClassicOldSong's Artemis speak to is untouched. All the new work is additive —
diagnostics, observability, and packaging — so existing clients pair, launch,
and reconnect exactly as before.
Not done yet
Hermes isn't 1.0. Setup, pairing UX, an appliance mode, the web-UI redesign,
and the remote-access / NAT story are still ahead. Treat 0.2.0 as a solid,
honest base — not the finished product.
Full Changelog: v0.1.0...v0.2.0